If you’re running Firefox 3.6, Mozilla strongly recommends you update to version 3.6.2. The new version corrects a critical security hole allowing an attacker to crash your browser and/or run arbitrary code on your machine.
The Security Warning advises:
Mozilla Foundation Security Advisory 2010-08
Title: WOFF heap corruption due to integer overflow
Impact: Critical
Announced: March 22, 2010
Reporter: Evgeny Legerov
Products: Firefox 3.6Fixed in: Firefox 3.6.2
DESCRIPTION
Security researcher Evgeny Legerov of Intevydis reported that the WOFF decoder contains an integer overflow in a font decompression routine. This flaw could result in too small a memory buffer being allocated to store a downloadable font. An attacker could use this vulnerability to crash a victim’s browser and execute arbitrary code on his/her system.
Note: Support for the WOFF downloadable font format is new in Firefox 3.6 (Gecko 1.9.2); this vulnerability does not affect products built on earlier versions of the Mozilla browser engine.
REFERENCES
Firefox recommends that all users upgrade to version 3.6.2 to correct this issue. The product can be downloaded from their website or by using the Check for Updates feature of the software.


[...] For more information, check out the post at VoIP Tech Chat. [...]
Firefox 3.6.2 Corrects Vulnerability | TEAM FORREST Blog
23 Mar 10 at 7:27 am
blogged: Got Firefox? Upgrade to 3.6.2. http://bit.ly/alHW9G
Fred Posner
23 Mar 10 at 12:17 pm
Updating FireFox right now! http://tr.im/T0l6
mjgraves
23 Mar 10 at 2:20 pm
[...] update follows another critical security hole less than 2 weeks earlier. The product can be downloaded from their website or by using the Check [...]
Firefox Security Vulnerability (Not an April Fool’s Joke) | VoIP Tech Chat
2 Apr 10 at 8:51 am